Malware

Win32/Injector.EEXD removal tips

Malware Removal

The Win32/Injector.EEXD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Injector.EEXD virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Detects VirtualBox through the presence of a file
  • Detects VMware through the presence of a file
  • Anomalous binary characteristics

How to determine Win32/Injector.EEXD?


File Info:

crc32: 09DEEAEF
md5: a049d28541fd2d12eb22cde4df9cb4f9
name: A049D28541FD2D12EB22CDE4DF9CB4F9.mlw
sha1: 9d4880d4715c826d9b0f74cc6b8e265784c4f746
sha256: 0d1de7409f5d91b199b669e067151bcc5789ede5f80daa3e961b43e21609901f
sha512: 65b3c1dd7656dcb31ad7c2b4151060dbd214c7ac9d1ecbdf67b800f5fae309b69dc7a771069c33d4a7b3d9a9ee1a342ca67e9b704ab89c489366cc4d2559c545
ssdeep: 12288:YEVnfYRfMSsAsR/2q1NLqxsA0qPCb1M/+BbXuDU:YsMMl/nTqxsA0qPQeI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Injector.EEXD also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Nanocore.23
MicroWorld-eScanGen:Variant.Barys.62751
FireEyeGeneric.mg.a049d28541fd2d12
McAfeeGenericRXHK-HX!A049D28541FD
CylanceUnsafe
SangforMalware
BitDefenderGen:Variant.Barys.62751
CrowdStrikewin/malicious_confidence_60% (D)
TrendMicroTrojanSpy.Win32.LOKI.SMAD2.hp
BitDefenderThetaGen:NN.ZelphiF.34590.JGW@aufRP8ki
CyrenW32/Trojan.CMD.gen!Eldorado
SymantecTrojan.Gen.2
APEXMalicious
ClamAVWin.Trojan.Fareit-7643055-1
Ad-AwareGen:Variant.Barys.62751
EmsisoftGen:Variant.Barys.62751 (B)
F-SecureHeuristic.HEUR/AGEN.1105404
InvinceaML/PE-A + Troj/Agent-AJFK
McAfee-GW-EditionBehavesLike.Win32.Fareit.hh
SophosTroj/Agent-AJFK
IkarusTrojan.Inject
MaxSecureTrojan.Malware.300983.susgen
AviraHEUR/AGEN.1105404
MicrosoftVirTool:Win32/CeeInject.BDQ!bit
ArcabitTrojan.Barys.DF51F
GDataGen:Variant.Barys.62751
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Delphiless.R326315
ALYacGen:Variant.Barys.62751
MAXmalware (ai score=83)
MalwarebytesTrojan.MalPack.DLF
ESET-NOD32a variant of Win32/Injector.EEXD
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.SMAD2.hp
RisingTrojan.Ymacco!8.11BE1 (TFE:2:bSRtW4lIhOQ)
YandexTrojan.GenAsa!SxBRusjpbFg
eGambitUnsafe.AI_Score_87%
FortinetW32/Injector.EHDJ!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.541fd2
AvastWin32:Trojan-gen

How to remove Win32/Injector.EEXD?

Win32/Injector.EEXD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment